msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names (word$$.html).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Catdoc | Catdoc | * | 0.91 (including) |